← Back to CVE List

CVE-2023-2422

Published: 2023-10-04T11:15Z
Last Modified: 2024-11-21T07:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt